Threat reportMalwareTL-2026-1995
WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europe
WindRelay + SpyNote Combo (TL-2026-1995), also tracked as WindRelay NFC Relay Combo, is a high-severity malware campaign, first published 2026-08-12. It has no confirmed attribution, affects Google Android, maps to 12 MITRE ATT&CK techniques (T1407, T1417, T1418), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1995
- Threat ID
- TL-2026-1995
- Also known as
- WindRelay NFC Relay Combo, WindRelay/SpyNote fraud scheme
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- finance, banking
- Target regions
- czechia, slovakia, slovenia, poland, Central Europe, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in WindRelay + SpyNote Combo
Malware and tooling: SpyNote, WindRelay
How WindRelay + SpyNote Combo works
Group-IB documents WindRelay, a newly tracked purpose-built Android NFC relay tool, deployed alongside the SpyNote RAT in a vishing-driven fraud scheme. Fraudsters posing as bank employees talk victims into sideloading a personalized SpyNote APK, then abuse its Accessibility Service access to silently install WindRelay, which relays live contactless card data to attacker-controlled devices for card-present purchases and ATM cash-outs, alongside fraudulent digital loans issued via banking-app takeover.
Group-IB's Fraud Protection team documented a two-malware Android fraud combo active across Central and Eastern Europe since at least November 2025. The scheme begins with a phone call in which the fraudster impersonates a bank employee and claims a problem with the victim's card, then walks the victim through installing an Android APK during the live call. That first-stage app is a personalized variant of the SpyNote RAT — the application label is set to the victim's own name, a deliberate trust-abuse tactic intended to lower suspicion since victims believe they are installing something sanctioned by their bank. SpyNote requests Accessibility Service permission, which it then abuses to silently sideload a second payload, WindRelay, via the device's package installer without triggering a visible screen-share prompt or requiring further victim interaction. WindRelay is Group-IB's newly tracked name for a purpose-built NFC relay tool: once installed, it instructs the victim (still on the phone with the fraudster) to tap their physical contactless payment card to their own handset and enter their PIN. WindRelay reads the live EMV contactless handshake off the NFC chip and streams it in real time over the internet to a second, attacker-controlled Android device, which replays the exchange at a real merchant POS terminal or ATM as if the victim's card were physically present, PIN included. In parallel, SpyNote's remote-control and Accessibility Service access is used to navigate the victim's mobile banking app and issue a fraudulent digital loan in the victim's name — a second monetization path pursued in the same call. Group-IB reports the entire sequence, from the first malicious install through the NFC capture and loan issuance, completes in as little as 13 minutes, well inside the window in which a victim could contact their bank to intervene. The operation has hit victims across Czechia, Slovakia, Slovenia, and Poland; Group-IB attributes the campaign via metadata correlation across 23 WindRelay and 7 SpyNote samples collected between November 2025 and July 2026, alongside 4 shared C2 IP addresses. Group-IB frames the technique as part of a broader, fast-growing NFC relay threat class: Kaspersky separately reported a 188% year-over-year increase in NFC-relay-style Android malware detections (35,600 blocked attacks January-April 2026 versus over 12,300 in the same period of 2025, across families including SuperCard X, PhantomCard, NGate, and modified NFCGate variants), and Group-IB's own prior research on 'Ghost Tap'/TX-NFC-style HCE card-emulation fraud documents a related but architecturally distinct NFC abuse pattern (relay app runs on the fraudster's device using stolen card credentials rather than live-relaying from the victim's phone) that has produced at least $355,000 in documented losses from a single point-of-sale vendor between November 2024 and August 2025.
MITRE ATT&CK techniques used in TL-2026-1995
Defense Evasion
T1407 Download New Code at Runtime
Collection
T1417 Input Capture; T1453 Abuse Accessibility Features; T1636.003 Contact List; T1638 Adversary-in-the-Middle
Discovery
Impact
T1516 Input Injection; T1657 Financial Theft
Persistence
Exfiltration
T1646 Exfiltration Over C2 Channel
Initial Access
Command and Control
Affected products and versions in WindRelay + SpyNote Combo
- Google — Android
Vulnerable versions: Android devices with sideloading/unknown-sources install enabled
Remediation for WindRelay + SpyNote Combo
Immediate actions
- Block outbound traffic to the 4 confirmed WindRelay C2 IPs at network/perimeter controls
- Push mobile threat defense / EDR signatures for the 23 WindRelay and 7 SpyNote sample hashes
- Alert bank fraud teams to correlate closely-timed digital loan requests with same-session card-present transactions
- Deploy out-of-band (SMS/app push) confirmation for any high-risk digital lending action initiated during or immediately after a phone call
Workarounds
- Disable 'install unknown apps' / sideloading permission on Android devices for non-technical users where feasible via MDM
- Restrict Accessibility Service grants to known, vetted applications via enterprise mobility management policy
Longer-term hardening
- Mobile threat defense (MTD) monitoring for apps requesting the NFC + Accessibility Service + INTERNET permission combination together
- Detect and flag Android package installs triggered from within an active phone call session (behavioral telemetry)
- Bank-side anomaly detection for card-present transactions occurring within minutes of a digital loan issuance on the same account
- Customer education campaigns explicitly warning that banks never ask customers to install an app or tap their card to their own phone during a call
Timeline of WindRelay + SpyNote Combo
- NFC relay attacks first documented against Czech Republic victims, predating the WindRelay/SpyNote combo, per Group-IB's prior threat tracking.
- Arrest made in Prague tied to earlier NFC relay fraud activity, referenced by Group-IB as prior regional context for the current campaign.
- Earliest WindRelay samples in Group-IB's 23-sample set date from November 2025, marking the start of the tracked campaign window.
- Group-IB publishes 'Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware,' documenting the related but distinct TX-NFC/Ghost Tap HCE-based relay fraud pattern.
- Kaspersky publicly reports a 188% year-over-year surge in NFC-relay-style Android malware detections for January-April 2026 (35,600 blocked attacks vs. 12,300+ in the same 2025 period), corroborating the growth of this technique class.
- Most recent WindRelay samples in Group-IB's dataset date from July 2026, indicating the campaign remained active through mid-2026.
- Trade press (GBHackers, Cybersecurity News) republish technical summaries of the Group-IB disclosure the same day, reiterating the 13-minute attack timeline and IOC counts.
- Group-IB publishes 'Gone with the WindRelay,' publicly disclosing the WindRelay NFC relay tool, its pairing with SpyNote, the 13-minute attack chain, victimology across Czechia, Slovakia, Slovenia and Poland, and full IOC set (4 C2 IPs, 23 WindRelay + 7 SpyNote SHA1 hashes).
Sources cited for WindRelay + SpyNote Combo
- Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
- WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud
- 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
- NFC relay attacks on smartphones surged by 188% in 2026, Kaspersky reveals
- Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware
- TX-NFC (Ghost Tap): NFC Relay Fraud Threat Profile
- SpyNote RAT, Software S0305
Detection coverage for TL-2026-1995
As of 2026-08-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1995 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.